threat-intel Zéro Logement Vacant visé par une fuite massive ? A hacker claims to have compromised Zéro Logement Vacant, a service of beta.gouv.fr, and extracted approximately 149 million lines of data, including information attributed to the DGFiP. The attack exploited a compromised Metabase administrator account and a PostgreSQL password stored in plain text. The hacker alleges… ZATAZ · 9h ago High FRmetabasepostgresqldata breach
vulnerability Multiples vulnérabilités dans Metabase (24 août 2026) Multiple vulnerabilities have been discovered in Metabase, allowing attackers to potentially compromise data confidentiality through SQL injection and an unspecified security issue. These vulnerabilities affect older ver… CERT-FR · 6d ago Medium CVE-2026-72898CVE-2026-72899CVE-2026-72900sql injectionvulnerabilitymetabase
threat-intel In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities This week’s cybersecurity news highlights a range of concerning developments, including a government contract sparking AI concerns, a North Korean IT worker infiltrating a US federal agency, vulnerabilities discovered in… SecurityWeek · Aug 14, 2026 High NOransomwarecyberattackvulnerability
threat-intel 14,000 Trezor Customers Impacted by Data Breach at ShipMonk Nearly 14,000 Trezor customers were affected by a data breach stemming from a vulnerability exploited by the ShinyHunters group within ShipMonk’s systems. The breach exposed customer data including names, addresses, emai… SecurityWeek · Aug 14, 2026 Medium USUKSWdata breachshippingvulnerability
vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach